chore: post-bankid redirect, recapt feedback, TIC SPAR enrichment (#400)

* chore: post-bankid redirect, recapt feedback, TIC SPAR enrichment

- BankID login + register now redirect to /select-company so the picker
  shows freshly enriched CompanyRoles from the current session.
- New lib/support/submit-feedback util prefers window.recapt feedback
  widget when present, falls back to /api/support/contact. SupportLink
  uses it and hides itself in sandbox companies via new isSandbox flag
  on CompanyContext (+ useCompanyOptional hook).
- TIC enrichment re-requests SPAR alongside CompanyRoles now that both
  types are enabled on the tenant; enrichment shape logged PII-free
  (booleans/counts only). Tests cover the SPAR+CompanyRoles path.
- Skatteverket api-client: 15s AbortSignal timeout on outbound requests.
- Swedish compliance review CI: bump REVIEW_MODEL to claude-opus-4-7.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore: keep compliance review model on sonnet-4-6

Reverts the opus-4-7 bump from the previous commit per request.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(tic): don't persist SPAR PII to extension_data

The previous commit started requesting SPAR alongside CompanyRoles and
wrote the full enrichment payload (incl. personnummer, full name, home
address, birth date, gender) verbatim to extension_data.value — a plain
JSON column. Personnummer is already hashed + encrypted in
bankid_identities, so the extension_data row was an unencrypted PII
duplicate exposed to anyone with read access to the table.

No consumer (middleware, /select-company, createCompanyFromTicRole)
reads any SPAR field today; they only read companyRoles. Persist a
sanitized blob of { companyRoles, enrichedAtUtc } instead. SPAR is
still requested from TIC (and its shape logged PII-free) so enrichment
completes; if address pre-fill ships later, those fields should be
encrypted before storage.

Also drop the dead `null` branch from SubmitFeedbackResult.channel —
every code path returns 'recapt' or 'email'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
Jakob Wennberg
2026-05-06 13:43:06 +02:00
committed by GitHub
co-authored by Claude Opus 4.7
parent 5725c25bf1
commit b9a2ce522b
11 changed files with 321 additions and 53 deletions
@@ -0,0 +1,104 @@
import { describe, it, expect, vi, beforeEach, afterEach } from 'vitest'
import { submitFeedback } from '@/lib/support/submit-feedback'
describe('submitFeedback', () => {
beforeEach(() => {
vi.unstubAllGlobals()
vi.restoreAllMocks()
})
afterEach(() => {
vi.unstubAllGlobals()
})
function stubRecapt(impl: (...args: unknown[]) => void) {
vi.stubGlobal('window', { recapt: impl })
}
function stubNoRecapt() {
vi.stubGlobal('window', {})
}
it('uses Recapt when SDK is present and prepends subject', async () => {
const recapt = vi.fn()
stubRecapt(recapt)
const fetchSpy = vi.fn()
vi.stubGlobal('fetch', fetchSpy)
const result = await submitFeedback({ subject: 'Hjälpsida', message: 'Hjälp tack' })
expect(result).toEqual({ ok: true, channel: 'recapt' })
expect(recapt).toHaveBeenCalledWith('feedback', { message: '[Hjälpsida]\n\nHjälp tack' })
expect(fetchSpy).not.toHaveBeenCalled()
})
it('uses Recapt without subject prefix when subject omitted', async () => {
const recapt = vi.fn()
stubRecapt(recapt)
await submitFeedback({ message: 'plain' })
expect(recapt).toHaveBeenCalledWith('feedback', { message: 'plain' })
})
it('falls back to email when Recapt throws', async () => {
stubRecapt(() => {
throw new Error('boom')
})
const fetchSpy = vi.fn().mockResolvedValue({
ok: true,
json: async () => ({}),
})
vi.stubGlobal('fetch', fetchSpy)
const result = await submitFeedback({ subject: 'X', message: 'msg' })
expect(result).toEqual({ ok: true, channel: 'email' })
expect(fetchSpy).toHaveBeenCalledWith(
'/api/support/contact',
expect.objectContaining({
method: 'POST',
body: JSON.stringify({ subject: 'X', message: 'msg' }),
})
)
})
it('falls back to email when Recapt SDK is absent', async () => {
stubNoRecapt()
const fetchSpy = vi.fn().mockResolvedValue({
ok: true,
json: async () => ({}),
})
vi.stubGlobal('fetch', fetchSpy)
const result = await submitFeedback({ message: 'msg' })
expect(result).toEqual({ ok: true, channel: 'email' })
expect(fetchSpy).toHaveBeenCalledOnce()
})
it('returns failure with error from email when fetch returns non-ok', async () => {
stubNoRecapt()
const fetchSpy = vi.fn().mockResolvedValue({
ok: false,
json: async () => ({ error: 'Mailtjänsten är inte konfigurerad' }),
})
vi.stubGlobal('fetch', fetchSpy)
const result = await submitFeedback({ message: 'msg' })
expect(result.ok).toBe(false)
expect(result.channel).toBe('email')
expect(result.error).toBe('Mailtjänsten är inte konfigurerad')
})
it('returns failure when fetch itself throws', async () => {
stubNoRecapt()
vi.stubGlobal('fetch', vi.fn().mockRejectedValue(new Error('Network down')))
const result = await submitFeedback({ message: 'msg' })
expect(result.ok).toBe(false)
expect(result.error).toBe('Network down')
})
})
+48
View File
@@ -0,0 +1,48 @@
export interface SubmitFeedbackInput {
message: string
subject?: string
}
export interface SubmitFeedbackResult {
ok: boolean
channel: 'recapt' | 'email'
error?: string
}
function composeMessage({ message, subject }: SubmitFeedbackInput): string {
if (!subject) return message
return `[${subject}]\n\n${message}`
}
async function submitViaEmail({ message, subject }: SubmitFeedbackInput): Promise<SubmitFeedbackResult> {
try {
const res = await fetch('/api/support/contact', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ subject, message }),
})
if (!res.ok) {
const data = await res.json().catch(() => ({}))
return { ok: false, channel: 'email', error: data.error || 'Kunde inte skicka meddelandet' }
}
return { ok: true, channel: 'email' }
} catch (err) {
return { ok: false, channel: 'email', error: err instanceof Error ? err.message : 'Nätverksfel' }
}
}
export async function submitFeedback(input: SubmitFeedbackInput): Promise<SubmitFeedbackResult> {
const recapt = typeof window !== 'undefined' ? window.recapt : undefined
const fullMessage = composeMessage(input)
if (typeof recapt === 'function') {
try {
recapt('feedback', { message: fullMessage })
return { ok: true, channel: 'recapt' }
} catch {
// fall through to email
}
}
return submitViaEmail(input)
}